CVE-2023-49621
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
- EPSS probability
- 0.15%
- CWE
- CWE-1392
- Published
- 2024-01-09
- Last modified
- 2026-03-13
Affected products
- Siemens SIMATIC CN 4100
Weakness type
Related vulnerabilities
- CVE-2024-12856 — Four-Faith Industrial Router adjust_sys_time OS Command Injection
- CVE-2025-8731 — TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
- CVE-2025-55051 — CWE-1392: Use of Default Credentials
- CVE-2025-12218 — Weak Default Credentials
- CVE-2023-3703 — Proscend Advice ICR Series routers fw version 1.76
- CVE-2023-30801 — qBittorrent Web UI Default Credentials Lead to RCE
- CVE-2023-30603 — Hitron Technologies Inc. CODA-5310 - Using default credentials
- CVE-2026-27751 — SODOLA SL902-SWTGW124AS <= 200.1.20 Use of Default Credentials